Two critical Chrome flaws put users at risk on malicious websites
Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
Threat actors are actively exploiting CVE-2026-9586, a recently patched SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3, targeting internet-exposed instances of the VoIP unified communications platform. Organizations running vulnerable Switchvox deployments should immediately check for signs of compromise and apply available patches to mitigate the ongoing exploitation risk.
Read full article at Help Net Security ↗Update Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.
SonicWall has patched two zero-day vulnerabilities affecting its SMA 1000 VPN appliances that are being actively exploited in the wild. The flaws, including a critical pre-authentication SSRF vulnerability with a CVSS score of 10.0, may be chained together by attackers to compromise affected systems. Security updates are now available to address these issues discovered during SonicWall's internal security review.
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold appeared first on SecurityWeek.
Two previously undisclosed zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in SonicWall SMA 1000 SSL VPN appliances are being actively exploited by attackers, as confirmed by the vendor. SMA 1000 devices are widely deployed by enterprises, government agencies, and managed security service providers for secure remote access, making this exploitation campaign a significant threat to critical infrastructure and business continuity.